Sunday, 18 July 2021

Working from home – is VPN safe anymore?


The pandemic struck and most of those people who usually worked from an office started working from home. Even mainframers were working on a laptop from home. The IT team needed a speedy way to get these people securely working from home and VPN became a three-letter acronym known to millions of people. Users were happy, they could work from home. Management were happy because their employees could work remotely. And hackers were happy because they could now pretty much gain access to every organization that they wanted!

For some people, the idea that virtual private networks (VPNs) aren’t secure must come as a shock, but anyone looking at the news this year will realize that VPN security has been a problem.

Before we look at what’s been in the news, let’s quickly remind ourselves what VPN is meant to do and how it works.

While everyone was safely inside their corporate offices working, they could access data and applications safely. However, once they were working remotely, they really needed a dedicated cable running from their laptop to the company network. This would be a private network just for them, and this would keep safe all the information passing backwards and forwards. However, this was never going to happen. So, users connected from home to office over the Internet. And in order to keep the packets of information safe, they used a virtual private network. In effect, there’s a virtual tunnel through the Internet from one end to the other. It keeps the information secure, and the activity anonymous. Sounds like the problem’s solved, doesn’t it?

Capcom, the video games developer in Japan, was hacked in November last year. It appears that Capcom’s US subsidiary retained an older VPN service as a backup, and this was used by the hackers to get into North American and Japanese networks, where they knocked out email and file servers. Apart from a ransomware demand, 390,000 individuals may have had their data compromised.

Zyxel has recently warned customers that its devices are being attacked, including security appliances having remote management or SSL VPN enabled, namely in the USG/ZyWALL, USG FLEX, ATP, and VPN series running on-premise ZLD firmware. Once hackers can access the device, they can connect to previously unknown accounts hardwired into the devices.

Worryingly, we hear that what's thought to be a North Korean hacking group has got into South Korea’s atomic research agency. Hackers breached the Korea Atomic Energy Research Institute (KAERI) network on 14 May using a VPN system vulnerability.

LimeVPN, VPN provider, has been hacked and 69,000 users have had their personal information stolen. A backup server was hacked that included a database of the details of all of LimeVPN's customers. The hackers claim to now possess the private key of every user, which means their data could be decrypted.

In the first quarter of this year, there was a 1,916% increase in attacks against Fortinet’s SSL-VPN. This was probably due to three different problems with the Fortinet FortiOS, Firstly, it seems that unauthenticated hackers could use specific HTTP resource requests on the SSL VPN web portal, which allowed them to download system files. Secondly, unauthenticated attackers on the same subnet could impersonate an LDAP server and intercept information. Thirdly, simply by changing the case of their username, hackers could successfully log in without being prompted for a second authentication factor. Clearly, anyone using Fortinet devices could be hacked, giving bad actors access to their network. The company has released patches to fix the vulnerabilities.

Also, in the first quarter of the year it’s been revealed that there has been a 1,527% increase in attacks on Pulse Connect Secure VPNs. In fact, in April the Metropolitan Transportation Authority (MTA) in New York revealed it was breached by hackers linked to the Chinese government. The Metropolitan Water District of Southern California and communications company, Verizon, were also targeted. It seems there was a zero-day vulnerability in Pulse Connect Secure VPN, which has now been patched.

Another attack using VPN was on Colonial Pipeline, which operates a pipeline from Texas to New Jersey and provides around 45 percent of the USA’s East Coast’s oil supplies. In this attack, hackers used an old VPN account that still provided access to the network. All they needed was a username and a password. The recommendation is that everyone uses multi-factor authentication when users login. And, all old accounts are removed, so they can’t be used to gain access to the network.

The problem is so serious that Help Net Security ran a headline in June saying, “VPN attacks up nearly 2000% as companies embrace a hybrid workplace”. Adding to everyone’s concern is the fact that US and British authorities have issued a joint advisory notice saying that Unit 26165, part of Russia's military spy agency, had been using VPNs and Tor to conduct "widespread, distributed, and anonymised brute force access attempts against hundreds of government and private sector targets". These include government offices, political parties, energy companies, law firms, and media organizations.

It makes sense now for every organization using VPN for their working-from-anywhere employees – and that includes companies that also have a mainframe – review the security of their VPN setup, and replace products where necessary or patch everything to the latest version. It might be a good idea to look at zero trust networks to keep checking that users are authorized and only doing what they’re authorized to do. And keep an ear to the ground for any news of VPN hacks and quickly respond. With nation states now using hacking teams in addition to criminal gangs, no-one is completely safe.

Sunday, 11 July 2021

Security and the pandemic

Having spent a number of hours each week talking and writing about security, I kind of assume that it’s a topic that everyone is interested in and that everyone is pretty much clued up about these days. Every company of any size uses external penetration testing (pentesting) experts to check that their systems are secure (even mainframes), and most companies nowadays seem to run dummy phishing attacks just to see which of their employees are still clicking on dodgy links and downloading questionable attachments. So, it was interesting to see the results of the IBM Consumer Survey: Security Side Effects of the Pandemic. The survey was carried out in March by Morning Consult, which asked 22,000 people around the world about their online security habits.

The key findings of the survey were:

  • Global respondents shifted further into digital interactions during COVID-19 and are likely to continue digital-first interactions in life after the COVID-19 pandemic.
  • Across all categories, global consumers created about 15 new online accounts during the pandemic. Younger respondents created more new accounts during the pandemic across categories, and created more accounts across each category than any other age group or generation.
  • Over four in five (82%) global respondents are re-using the same credentials that they have used for other accounts at least some of the time. Younger respondents are more likely to say they always or mostly re-use the same credentials that they have used for other accounts.
  • Many would still rather place an order digitally – even if there were security/privacy concerns. Over four in ten (44%) global respondents, and 51% of millennials would rather place and pay for an order digitally than go to a physical location or call to place an order even if they had concerns about the website/app’s safety or privacy.
  • A majority of global respondents (63%) accessed COVID-related services via digital channels – including mobile apps, websites, email, and text messages.
  • Nearly half (44%) of respondents do not plan to delete or deactivate any of the new accounts they created during the pandemic after society returns to pre-pandemic norms.

The report says that “consumers not only increased their reliance on digital channels during the pandemic, but also that this ‘digital dependence’ is expected to linger even after society returns to pre-pandemic norms. Consumers reported they will continue to rely on digital services at higher rates than before the pandemic, and many say they will not delete any of the new accounts they created during that time.”

The survey found that respondents under 50 are most likely to predict they will interact through digital formats in life after the COVID-19 pandemic. Although the average number of new accounts was 15, millennials created over 18 new online accounts during the pandemic, more than any other generation. The only slightly good news was that the survey found that 56% respondents would remove permission for an application to track behaviour if the app requested permission to do so.

The survey concludes that “consumers’ increased reliance on digital channels during the pandemic may have caused more lax attitudes towards security – with the convenience of digital ordering often outweighing security and privacy concerns. Many consumers (particularly younger generations) say they would rather place an order digitally, even if there were security or privacy concerns with the application. Additionally, consumers rarely decline to use a new digital platform due to security or privacy concerns. This surge in new accounts may also be creating password fatigue, with consumers reporting high levels of password reuse across their accounts. This means many of the new accounts created during the pandemic likely relied on reused credentials, which may have been compromised in previous data breaches.

The survey also found that 35% of respondents have accepted terms they were uncomfortable with so they could use a service. 41% would avoid using an online platform to shop or place an order over concerns over app/website security, and 38% would avoid using online platforms if they had concerns around privacy.

For vendors, a bad online user experience can lead to people giving up on an online purchase, application, or transaction based on negative experiences. 42% said they’d done that when logging in, 41% when signing up, and 41%, again, when completing payment. Younger respondents are more likely to give up than older people. The survey also found that, on average, respondents across all age groups would attempt about 3-4 logins before they decided to reset their login credentials.

While 59% of respondents expect to spend between 1-5 minutes setting up a new digital account, 57% would reconsider setting up a non-essential digital account after spending 1-5 minutes. 44% of respondents keep online account information in their memory, and 32% have it written on paper. And while passwords are the preferred method to log in, respondents under 35 are more likely than older generations to prefer single sign-on or biometrics. It’s good to see that around two thirds of respondents have used two-factor or multi-factor authentication to access an online account. 65% of respondents are very or somewhat familiar with the concept of digital credentials, and 76% of respondents would be very or somewhat likely to use digital credentials.

63% of respondents have accessed COVID-related services via digital channels, and younger respondents were more likely to have accessed COVID related services digitally.

Overall, it’s an interesting, but worrying survey. IBM Security did offer companies the following guidance:

“Zero Trust Approach: given increasing risks, companies should consider evolving to a ‘zero trust’ security approach, which operates under the assumption that an authenticated identity, or the network itself, may already be compromised – therefore, it continuously validates the conditions for connection between users, data, and resources to determine authorization and need. This approach requires companies to unify their security data and approach, with the goal of wrapping security context around every user, every device, and every interaction.

“Modernizing Consumer IAM: investing in a modernized Consumer Identity and Access Management (CIAM) strategy can help companies increase digital engagement – providing a frictionless user experience across digital platforms and using behavioural analytics to decrease the risk of fraudulent account use.

“Data Protection & Privacy: having more digital users means that companies will also have more sensitive consumer data to protect. Organizations must ensure that strong data security controls are in place to prevent unauthorized access – from monitoring data to detect suspicious activity, to encrypting sensitive data wherever it travels. Companies should also implement the right privacy policies on premise, and in the cloud, in order to maintain consumer trust.

“Put Security to the Test: with usage and reliance on digital platforms changing rapidly, companies should consider dedicated testing to ensure the security strategies and technologies they’ve relied on previously still hold up in this new landscape. Re-evaluating the effectiveness of incident response plans, and testing applications for security vulnerabilities, are both important components of this process.”

Good advice.

 

Sunday, 4 July 2021

Mainframes not going away any time soon

The latest research about mainframe market size, market share, application analysis, regional outlook, growth trends, key players, competitive strategies, and forecasts for 2021 to 2029 have been published by Research and Markets.

They say that the global mainframe market is projected to witness a substantial growth, growing at a compound annual growth rate (CAGR) of 3.2 percent during the forecast period from 2021 to 2029, according to a new report added to ResearchAndMarkets.com website.

Not surprisingly, they say that, based on geography, North America led the overall mainframe market accounting for the largest market share in 2020. The region is likely to remain market leader throughout the forecast period from 2021 to 2029. 

The presence of some major players, such as IBM, BMC Software, Dell, and Hitachi Vantara, also supports the growth of the market and is expected to provide lucrative opportunities in the years to come, according to the report. In North America, the USA dominated the regional mainframe market in 2020, and is projected to reign throughout the forecast period from 2021 to 2029, the report claimed.

The report informs us that mainframe manufacturers are adopting strategies like new product development and partnerships to cater for the needs of their customers and gain competitive advantage over other players. The major players in the mainframe market include Atos SE, BMC Software, CA Technologies, Cognizant, Dell, DXC Technology Company, FUJITSU, HCL Technologies Limited, Hitachi Vantara Corporation, Infosys Limited, IBM, LzLabs GmbH, Redcentric, Unisys, ViON, and Wipro, among others.

The full report looks at segmentation by product type, including Z Systems, GS 21 Series, and others. There’s end-use vertical segment, including BFSI, Healthcare, Defense & Government, Retail, Public Utilities, and others (Academics and Research, etc). And there is geography, looking at North America (USA and Rest of North America), Europe (UK, Germany, France, Rest of Europe), Asia Pacific (Japan, China, India, Rest of APAC), and the rest of the world (Middle East & Africa, Latin America).

The list of key questions answered in the report are:

  • What was the market size of mainframe market in 2020 and forecast up to 2029?
  • What are the key factors driving the global mainframe market?
  • What are the key market trends and high-growth opportunities observed in the mainframe market?
  • What are the drivers of the mainframe market?
  • Which is the largest regional market for mainframe market?
  • Which segment will grow at a faster pace? Why?
  • Which region will drive the market growth? Why?
  • Which players are leading the mainframe market?
  • What are the sustainability strategies adopted by the key players operating in the market?

The trouble with any report like this, certainly looking towards the end of the decade is that, obviously, it cannot predict unexpected events. Its biggest assumption is that life will pretty much carry on as normal – and not allow for pandemics and other crises occurring. However, as that’s the way all of us plan for the future, that’s not too much of a criticism.

The good news for those of us who work in the mainframe world is that the predictions are that the mainframe market will continue to grow over the next eight years, which indicates that we will still be in paid employment for the foreseeable future. Although, perhaps our employment prospects might become in doubt as AI and machine learning make experienced mainframers less needed to run these new machines of the future.

And, there’s always the possibility that mainframes will be replaced by fully functional quantum computers in a few years’ time. And that will have a devasting effect on predictions for the mainframe marketplace by the end of the decade.

Perhaps many mainframers are simply hoping that the industry will still be around until it’s time for them to retire!